* feat: add casbin admin permissions * feat: improve audit logging to associate logs with actual operators and target users * feat: enhance admin permissions and UI interactions for sensitive actions * Refactor authz RBAC and tighten channel permissions * Split channel authz field policy * Address channel authz review findings
28 lines
585 B
Go
28 lines
585 B
Go
package authz
|
|
|
|
import "strconv"
|
|
|
|
// Permission identifies a single action on a resource.
|
|
type Permission struct {
|
|
Resource string
|
|
Action string
|
|
}
|
|
|
|
// PermissionsMap is a resource -> action -> allowed lookup.
|
|
type PermissionsMap map[string]map[string]bool
|
|
|
|
const (
|
|
EffectAllow = "allow"
|
|
EffectDeny = "deny"
|
|
)
|
|
|
|
// UserSubject is the casbin subject string for a single user.
|
|
func UserSubject(userID int) string {
|
|
return "user:" + strconv.Itoa(userID)
|
|
}
|
|
|
|
// RoleSubject is the casbin subject string for a role.
|
|
func RoleSubject(roleKey string) string {
|
|
return "role:" + roleKey
|
|
}
|